# SPDX-License-Identifier: AGPL-3.0-only # Copyright 2026-present the Unsloth AI Inc. team. All rights reserved. # Mac counterpart to studio-api-smoke.yml. Same tests/studio/ # studio_api_smoke.py exercise (CORS hardening, auth state machine, # JWT expiry, API key lifecycle, /v1/models / /v1/embeddings / # /v1/responses, endpoint-by-endpoint auth audit) but on a real # Apple Silicon (macos-14, M1) runner. Drops the apt-get block; # GitHub-hosted macos-14 ships curl + jq. name: Mac Studio API CI on: pull_request: paths: - 'studio/**' - 'unsloth/**' - 'unsloth_cli/**' - 'install.sh' - 'pyproject.toml' - 'tests/studio/**' - '.github/workflows/studio-mac-api-smoke.yml' push: branches: [main, pip] workflow_dispatch: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true permissions: contents: read jobs: api-smoke: name: Studio API & Auth Tests runs-on: macos-14 timeout-minutes: 25 env: GGUF_REPO: unsloth/gemma-3-270m-it-GGUF GGUF_VARIANT: UD-Q4_K_XL GGUF_FILE: gemma-3-270m-it-UD-Q4_K_XL.gguf STUDIO_PORT: '18895' HF_HOME: ${{ github.workspace }}/hf-cache steps: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: '22' cache: 'npm' cache-dependency-path: studio/frontend/package-lock.json - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: python-version: '3.12' cache: 'pip' - name: Cache HF_HOME for ${{ env.GGUF_REPO }} id: cache-hf uses: actions/cache@v4 with: path: hf-cache key: ${{ runner.os }}-hf-${{ env.GGUF_REPO }}-${{ env.GGUF_VARIANT }}-v1 - name: Prime HF_HOME with the GGUF if: steps.cache-hf.outputs.cache-hit != 'true' run: | python -m pip install --upgrade huggingface_hub hf_transfer mkdir -p hf-cache HF_HUB_ENABLE_HF_TRANSFER=1 \ hf download "$GGUF_REPO" "$GGUF_FILE" - name: Install Studio (--local, --no-torch) env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | mkdir -p logs set -o pipefail bash install.sh --local --no-torch 2>&1 | tee logs/install.log - name: Assert install.sh used the Mac llama.cpp prebuilt run: | if grep -q "falling back to source build" logs/install.log; then echo "::error::install.sh fell back to source-build llama.cpp on Mac. Studio must install the prebuilt llama-bNNNN-bin-macos-arm64 on Apple Silicon." grep -E "llama-prebuilt|llama.cpp" logs/install.log | tail -60 exit 1 fi - name: Install pyjwt for the JWT-expiry forge test run: pip install 'pyjwt>=2.6' - name: Reset auth + boot Studio (API-only) run: | unsloth studio reset-password mkdir -p logs UNSLOTH_API_ONLY=1 unsloth studio -H 127.0.0.1 -p "$STUDIO_PORT" \ > logs/studio.log 2>&1 & echo "STUDIO_PID=$!" >> "$GITHUB_ENV" - name: Wait for /api/health run: | for i in $(seq 1 180); do if curl -fs "http://127.0.0.1:${STUDIO_PORT}/api/health" > /tmp/health.json; then jq -e '.status == "healthy"' /tmp/health.json && break fi sleep 1 done jq -e '.status == "healthy"' /tmp/health.json - name: Pass bootstrap password + rotated targets to the test run: | OLD=$(cat ~/.unsloth/studio/auth/.bootstrap_password) NEW="ApiSmoke-$(python -c 'import secrets; print(secrets.token_urlsafe(16))')" NEW2="ApiSmoke-$(python -c 'import secrets; print(secrets.token_urlsafe(16))')" echo "::add-mask::$OLD" echo "::add-mask::$NEW" echo "::add-mask::$NEW2" echo "STUDIO_OLD_PW=$OLD" >> "$GITHUB_ENV" echo "STUDIO_NEW_PW=$NEW" >> "$GITHUB_ENV" echo "STUDIO_NEW2_PW=$NEW2" >> "$GITHUB_ENV" - name: Run Studio API & Auth tests env: BASE_URL: http://127.0.0.1:18895 STUDIO_AUTH_DIR: /Users/runner/.unsloth/studio/auth run: python tests/studio/studio_api_smoke.py - name: Stop Studio if: always() run: | kill "${STUDIO_PID}" 2>/dev/null || true sleep 2 - name: Upload API smoke logs if: always() uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: mac-studio-api-smoke-log path: | logs/install.log logs/studio.log retention-days: 7